logo

CVE-2026-31431 (Copy Fail): Linux Kernel LPE

ID: ab5d71e4-0978-5f5e-a57f-e302cd14b7ec

STIX ID: report--ab5d71e4-0978-5f5e-a57f-e302cd14b7ec

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Dor Hayun

...
...

A public advisory describes CVE-2026-31431 (Linux "Copy Fail" LPE): a deterministic local privilege escalation in the kernel's algif_aead path (reachable via AF_ALG and splice()) that can write four bytes into any readable file's page cache allowing reliable root escalation and container escapes; the report lists affected kernels (4.14 through fixed releases), mitigation steps (disable algif_aead, block AF_ALG via seccomp, patch and reboot), and links to the original Mend blog post.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.